Impact
The Small Package Quotes – Worldwide Express Edition plugin contains an SQL injection flaw that allows an attacker to inject arbitrary SQL statements into the database. This vulnerability could enable the attacker to read, modify, or delete data stored in the WordPress database. The impact is limited to the exploited site's database, but the compromise could lead to loss of data integrity and confidentiality for that installation. The flaw originates from improperly escaping or validating user input before incorporating it into SQL commands.
Affected Systems
WordPress sites that have installed any version of the enituretechnology Small Package Quotes – Worldwide Express Edition plugin through version 5.2.17 are affected. This includes all builds from the earliest available release (indicated as n/a) up to and including 5.2.17. No other WordPress plugins or external products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical vulnerability. The EPSS score of less than 1% suggests exploitation is rare but possible in the wild. The plugin is publicly reachable via the site’s web interface, so the attack vector is most likely over the network. While the vulnerability does not explicitly provide remote code execution, the breadth of database control could potentially be leveraged by an attacker to impact site availability or to execute further exploits if additional weaknesses exist. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD